MaximaLabs
Enterprise

The process engineering platform IT actually approves

Private-by-default simulations, role-based access, real-time multiplayer, and a security posture stated plainly — no certifications we don't hold, no vague data-sovereignty promises.

Feed
Reactor
Separator
Product
Recycle

The same rigorous solver every engineer uses, running entirely in the browser — nothing to install, patch, or push out to a fleet of workstations.

Built around what IT, security, and engineering leadership actually ask

Not a feature list — the three questions that gate a rollout.

IP protection & data isolation

Simulations are private by default — visible only to their owner and explicitly invited collaborators, with owner/editor/viewer roles per simulation. Encryption in transit, isolated per-deployment storage, and CSV/PDF export on demand — see the full posture on the security page.

Deployment & lifecycle

Browser-based — no desktop agent, installer, or client patch cycle for IT to maintain. Sign in with your enterprise IdP via SAML 2.0 SSO (Okta, Azure AD, Ping), Google SSO, or email/password; organizations and projects group teams with their own membership and default settings.

Scale & collaboration

Solves run as background jobs so the UI never blocks, sensitivity sweeps and Monte Carlo studies run the same way, and real-time multiplayer (the same conflict-free sync engine behind Google Docs-style editing) lets teams co-design a flowsheet on one canvas instead of emailing files.

Live multiplayer, not emailed .hsc files

Two engineers, one canvas, no merge conflicts.

Reactor
Flash
Alice
Bob

Trust & compliance

What's real today, linked to where we actually say it — not restated differently in two places.

Access & governance

Role-based access at the simulation level (owner/editor/viewer) and the organization/project level (admin/member), plus real per-org SAML 2.0 SSO (Okta/Azure AD/Ping) alongside Google SSO and email/password. A SAML login auto-grants org membership — no separate provisioning step. No domain-based auto-join policy or a general audit log beyond the flowsheet commit history exists yet — we'd rather tell you that than imply otherwise.

Compliance

SOC 2 Type II — on our roadmap, not yet held. We don't display certifications we haven't earned; full detail and current controls are on the security page.

Plant & data integrations

OPC-UA, Modbus TCP, EtherNet/IP, MQTT/Sparkplug B for live plant telemetry, plus a full Python SDK and REST/WebSocket API for programmatic access.

What actually leaves your network

One call, and it's non-blocking — not a vague 'trust us.'

  • The Anthropic API call the AI copilot makes to diagnose a failed solve or draft a flowsheet — nothing else.
  • If that call is blocked, slow, or disabled, every solve still runs: the AI path is never on the critical solve path, so results still render and the copilot just shows "diagnostics unavailable."
  • The solver, the database, file storage, and every stream/flowsheet value stay on your infrastructure the entire time in self-hosted mode.

We don't publish case studies we can't verify

No anonymized "35% reduction" claims here — a replication only gets published once it's actually been done and checked against a real source. If that policy sounds unusually strict, that's the point: see the case-study program (and request one).

Frequently asked

How does authentication work?

Email/password (bcrypt-hashed), Google SSO, or real per-organization SAML 2.0 SSO (Okta, Azure AD, Ping) — an org admin configures their IdP's entity ID/SSO URL/certificate directly in the app, no support-assisted setup required. Every session rides a signed, httpOnly cookie — no tokens stored in the client.

Who can see or fork a simulation?

Simulations are private by default — visible only to their owner and anyone explicitly added as a collaborator (viewer, editor, or owner). Organizations and projects layer a second, coarser membership tier (admin/member) for grouping teams and default settings. Nothing is publicly listable just because it exists.

What's your compliance timeline?

We're building toward SOC 2 Type II and don't claim certifications we don't hold. If a formal security review is a prerequisite for your team, tell us where you are in procurement and we'll share our current controls and timeline.

Can we run this inside our own network?

Yes — the same Docker Compose stack that runs the hosted product deploys inside your infrastructure instead of ours. See exactly what leaves your network below.

See it on your own process

Every number on this page comes from a real, converged flowsheet — open the workspace and run one yourself.

Stop fighting legacy software. Build your first flowsheet in 60 seconds.